Overview
What this lab demonstrated
Rather than targeting a server service, this exercise used a vulnerable browser as the entry point. The Windows client visited a Kali-hosted lab URL, processed controlled exploit content, retrieved a test payload from a separate local web server, and established a reverse session back to the lab handler.
The work was completed only on self-managed virtual machines in an isolated course environment. This page intentionally keeps the implementation high-level and does not publish live payloads, exact commands, or downloadable artifacts.